CVE-2026-48840: Exim 4.99.4: PROXY-protocol uninitialised-stack information disclosu
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/exim4to a version that resolves this vulnerability.Fixed in 4.96-15+deb12u10Fixed in 4.98.2-1+deb13u3Fixed in 4.99.3-2 - Upgrade
Upgrade
eximto a version that resolves this vulnerability.Fixed in 4.99.4 - Compensating control
For proxy configurations where Exim may mishandle short payloads, review and restrict proxy/proxy-protocol access paths so untrusted clients cannot directly reach the affected proxy-protocol handling behavior.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48840?
The severity of CVE-2026-48840 is rated as medium with a score of 5.3.
How do I fix CVE-2026-48840?
To mitigate CVE-2026-48840, upgrade Exim to version 4.99.4 or later.
What type of vulnerability is CVE-2026-48840?
CVE-2026-48840 is an information disclosure vulnerability related to uninitialized stack memory.
Which software versions are affected by CVE-2026-48840?
CVE-2026-48840 affects Exim versions prior to 4.99.4 in specific proxy configurations.
What is the impact of CVE-2026-48840?
CVE-2026-48840 can lead to the disclosure of uninitialized stack memory values to a client.